OilRig DNS TXT C2 Beaconing via nslookup/PowerShell/cmd (ALMA Communicator/BONDUPDATER)

This rule detects potential command and control (C2) beaconing activity associated with the OilRig threat group's BONDUPDATER/ALMA Communicator malware. It identifies suspicious, highly regular DNS TXT record queries (QueryType 16) originating from common system tools like nslookup.exe, powershell.exe, or cmd.exe. The detection logic calculates the statistical regularity of query intervals to identify automated beaconing patterns, which is a hallmark of C2 communication using DNS tunneling or data exfiltration via DNS.